CVE-2010-3035
Last modified
CVE-2010-3035 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.. CISA has confirmed active exploitation in the wild. EPSS estimates a 5.56% chance of exploitation in the next 30 days.
Description
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | >= 3.4.0, <= 3.9.1 |
References
- http://osvdb.org/67696Broken Link
- http://secunia.com/advisories/41190Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlBroken Link, Vendor Advisory
- http://www.securitytracker.com/id?1024371Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443VDB Entry, Vendor Advisory
- http://osvdb.org/67696Broken Link
- http://secunia.com/advisories/41190Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlBroken Link, Vendor Advisory
- http://www.securitytracker.com/id?1024371Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443VDB Entry, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3035US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2010-3035?
How severe is CVE-2010-3035?
How do I fix CVE-2010-3035?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3029SQL injection vulnerability in statistics.php in PHPKick 0.8…
- CVE-2010-3030Cross-site request forgery (CSRF) vulnerability in Tomaz Mur…
- CVE-2010-3031Buffer overflow in Wyse ThinOS HF 4.4.079i, and possibly oth…
- CVE-2010-3032Integer overflow in the OBGIOPServerWorker::extractHeader fu…
- CVE-2010-3033Cisco Wireless LAN Controller (WLC) software, possibly 4.2 t…
- CVE-2010-3034Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x…
- CVE-2010-3036Multiple buffer overflows in the authentication functionalit…
- CVE-2010-3037goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconf…
- CVE-2010-3038Cisco Unified Videoconferencing (UVC) System 5110 and 5115, …
- CVE-2010-3039/usr/local/cm/bin/pktCap_protectData in Cisco Unified Commun…
- CVE-2010-3040Multiple stack-based buffer overflows in agent.exe in Setup …
- CVE-2010-3041Multiple buffer overflows in the Cisco WebEx Recording Forma…
Are you affected by CVE-2010-3035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
